T1600 Registry-based Weakening of TLS/Cipher/FIPS Configuration
This rule detects unauthorized modifications to sensitive Windows registry keys related to SCHANNEL ciphers, protocols, or FIPS algorithm policies. It specifically identifies when these security settings are weakened (e.g., enabling insecure algorithms or disabling security defaults) by interactive users rather than authorized system processes or configuration management tools like Intune or SCCM.
Microsoft Sentinel (KQL)

